Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3076▲ 446 respecto a la semana anterior
Críticas / altas1457▲ 26 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)237▲ 223 respecto a la semana anterior
23.740 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (6.5) | 0.41% | — | Django CMSAI | 20/8/2026 | 9/9/2026 | django CMS is an easy-to-use and developer-friendly enterprise content management system powered by Django. Prior to 5.0.8, render_object_structure in cms/views.py renders cms/toolbar/structure.html for a PageContent object without calling user_can_view_page(). Any staff account can request a restricted page’s… | |
| Pendiente de análisis | Media (6.5) | 0.41% | — | Django-cms Django CMSAI | 20/8/2026 | 9/9/2026 | django CMS is an easy-to-use and developer-friendly enterprise content management system powered by Django. Prior to 5.0.8, the copy_plugins endpoint in cms/admin/placeholderadmin.py authorizes only the destination clipboard. The _copy_plugin_to_clipboard and _copy_placeholder_to_clipboard paths accept… | |
| Aplazada | Media (6.5) | 0.41% | — | Django CMSAI | 20/8/2026 | 18/9/2026 | django CMS is an easy-to-use and developer-friendly enterprise content management system powered by Django. Prior to 5.0.9, page duplication lacks an object-level authorization check on the source page. In cms/admin/forms.py, DuplicatePageForm.source accepts any Page, the AddPageForm constructor does not narrow a… | |
| Analizada | Media (5.4) | 0.41% | — | Cesanta Mongoose | 20/8/2026 | 29/9/2026 | Mongoose is an embedded web server and network library. Prior to 7.22, a remote attacker can send a crafted percent-encoded request path to a deployment using MG_ENABLE_DIRLIST and persuade a user to visit it. The mg_http_serve_dir() and listdir() path in src/http.c places the decoded request URI into the title and h1… | |
| Analizada | Media (6.5) | 0.46% | — | Cesanta Mongoose | 20/8/2026 | 29/9/2026 | Mongoose is an embedded web server and network library. Prior to 7.22, a remote attacker can place a lone carriage return or line feed in multipart input processed by mg_http_next_multipart() in src/http.c. The loops comparing s[b] and s[b + 1], and s[h2] and s[h2 + 1], use an incorrect AND condition and stop when… | |
| Analizada | Crítica (9.1) | 0.67% | — | Cesanta Mongoose | 20/8/2026 | 29/9/2026 | Mongoose is an embedded web server and network library. Priro to version 7.22, a remote unauthenticated attacker can send an HTTP request containing both Content-Length and Transfer-Encoding: chunked. The cl_count and te_count checks in the mg_http_parse() and http_cb() paths in src/http.c accept both headers and… | |
| Analizada | Crítica (9.1) | 0.44% | — | Cesanta Mongoose | 20/8/2026 | 29/9/2026 | Mongoose is an embedded web server and network library. Prior to 7.22, a remote unauthenticated attacker can exploit an HTTP/1.0 reverse-proxy deployment by sending a request with Transfer-Encoding: chunked and conflicting framing. The http_cb() function in src/http.c tests hm.proto.len with an impossible… | |
| Analizada | Media (6.5) | 0.66% | — | Cesanta Mongoose | 20/8/2026 | 29/9/2026 | Mongoose is an embedded web server and network library. Prior to 7.22, an attacker who can control an SSI-enabled file can place directory traversal sequences in an #include file or #include virtual directive. The mg_ssi() function in src/ssi.c concatenates the directive argument into a filesystem path without calling… | |
| Analizada | Media (5.4) | 0.34% | — | Cesanta Mongoose | 20/8/2026 | 29/9/2026 | Mongoose is an embedded web server and network library. Prior to 7.22, an attacker who can create a file with an HTML payload in its name can trigger stored cross-site scripting when a user browses a directory served with MG_ENABLE_DIRLIST. The printdirentry() path called by listdir() in src/http.c URL-encodes the… | |
| Analizada | Crítica (9.1) | 0.34% | — | Cesanta Mongoose | 20/8/2026 | 29/9/2026 | Mongoose is an embedded web server and network library. Prior to version 7.22, an on-path network attacker with a wildcard certificate for a parent domain can impersonate deeper subdomains to a client using the built-in TLS stack. The mg_tls_verify_cert_san() and mg_tls_verify_cert_cn() functions in src/tls_builtin.c… | |
| Analizada | Crítica (9.3) | 0.19% | — | Cesanta Mongoose | 20/8/2026 | 29/9/2026 | Mongoose is an embedded web server and network library. Prior to 7.23, a network attacker can impersonate a TLS server to a Mongoose client configured with a multi-certificate CA bundle. In src/tls_builtin.c, the mg_tls_init() function stores the bundle in tls->ca_bundle_der while tls->ca_der.len remains zero, and… | |
| Aplazada | Media (4.8) | 0.18% | — | Django CMSAI | 20/8/2026 | 18/9/2026 | django CMS is a content management system powered by Django. Prior to 5.0.8 and in 5.1.0a1, the django CMS page cache in cms/cache/page.py ignores request headers declared by plugins through get_vary_cache_on(). The _page_cache_key function includes the cache prefix, site, language, path, and timezone but not the… | |
| Aplazada | Alta (7.1) | 0.49% | — | Django CMSAI | 20/8/2026 | 18/9/2026 | django CMS is an easy-to-use and developer-friendly enterprise content management system powered by Django. Prior to 5.0.8, the move_plugin endpoint in cms/admin/placeholderadmin.py accepts an attacker-controlled plugin_parent value without rejecting a plugin’s own identifier or a descendant identifier. A staff user… | |
| Aplazada | Crítica (9.9) | 0.48% | — | Warehouse CargoAI | 20/8/2026 | 20/8/2026 | Subscriber Arbitrary File Upload in Warehouse Cargo <= 2.6.9 versions. | |
| Aplazada | Alta (8.1) | 0.47% | — | Uxper GoloAI | 20/8/2026 | 20/8/2026 | Unauthenticated Local File Inclusion in Golo Framework < 1.7.5 versions. | |
| Analizada | Media (5.5) | 0.14% | — | Hashicorp Go-slug | 19/8/2026 | 4/9/2026 | HashiCorp go-slug 0.4.0 through 0.18.2 could allow a local attacker to bypass .terraformignore exclusions and cause sensitive files to be included in Terraform slug uploads due to improper handling of Unicode normalization during path matching. | |
| Aplazada | Alta (7.5) | 0.70% | — | Thecodingmachine GotenbergAI | 19/8/2026 | 9/9/2026 | Gotenberg is a Docker-powered stateless API for PDF files. From 8.10.0 until 8.33.0, the newContext function in pkg/modules/api/context.go starts one errgroup.Go goroutine for each multipart downloadFrom entry and allows those goroutines to concurrently write to the shared ctx.files, ctx.diskToOriginal, and… | |
| Aplazada | Alta (7.5) | 0.37% | — | Thecodingmachine GotenbergAI | 19/8/2026 | 9/9/2026 | Gotenberg is a Docker-powered stateless API for PDF files. In 8.32.0 and earlier, the IsPublicIP function in pkg/gotenberg/outbound.go does not reject the 2002::/16 6to4 prefix, the 64:ff9b::/96 and 64:ff9b:1::/48 NAT64 prefixes, the fec0::/10 deprecated site-local prefix, Teredo, and other transition prefixes that… | |
| Aplazada | Alta (8.8) | 0.50% | — | Thecodingmachine GotenbergAI | 19/8/2026 | 9/9/2026 | Gotenberg is a Docker-powered stateless API for PDF files. In 8.32.0 and earlier, filename handling in pkg/modules/api/context.go uses filepath.Base on Linux, which does not treat backslashes as path separators, so a multipart filename containing Windows-style parent directory components survives sanitization. The… | |
| Pendiente de análisis | Media (6.8) | 0.29% | — | RenovateAIBazeliskAIGoogle BazelAI | 19/8/2026 | 8/10/2026 | Renovate versions from 43.65.0 before 43.102.11 contain a remote code execution vulnerability in bazel-module and bazelisk managers when using lockFileMaintenance. Attackers can execute arbitrary code by providing malicious dependencies that are referenced in bazel mod deps calls, such as within ctx.execute statements. | |
| Analizada | Alta (8.8) | 0.45% | — | Google Chrome | 18/8/2026 | 20/8/2026 | Type confusion in V8 in Google Chrome prior to 151.0.7922.169 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High) | |
| Analizada | Alta (8.3) | 0.37% | — | Google Chrome | 18/8/2026 | 21/8/2026 | Buffer overflow in ANGLE in Google Chrome on on Android prior to 151.0.7922.169 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) | |
| Analizada | Alta (8.8) | 0.52% | — | Google Chrome | 18/8/2026 | 21/8/2026 | Use after free in WebGL in Google Chrome prior to 151.0.7922.169 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High) | |
| Analizada | Alta (8.3) | 0.32% | — | Google Chrome | 18/8/2026 | 21/8/2026 | Race condition in USB in Google Chrome prior to 151.0.7922.169 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) | |
| Analizada | Alta (8.8) | 0.41% | — | Google Chrome | 18/8/2026 | 21/8/2026 | Incorrect calculation in V8 in Google Chrome prior to 151.0.7922.169 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High) |